Privacy Policy
This Privacy Policy explains how Frosty World LLC ("Coinhost", "we", "us") collects, uses, and protects information when you use the Coinhost website (coinhost.com), the Coinhost Wallet mobile application, and related services (together, the "Services"). Coinhost is a Bitcoin self-custody product and consultancy. We have built the Services to collect as little personal information as possible.
1Who we are
The Services are operated by Frosty World LLC, a Delaware limited liability company. For any privacy question, or to exercise your rights below, contact us atprivacy@coinhost.com. Our postal address is at the end of this policy.
2Information we collect
Information you give us
- Waitlist & consultation requests. When you join the waitlist or submit the consultation form, we collect your email address and any details you choose to provide (such as your name and your message).
- Account information (app). To use Coinhost Wallet you provide an email address and configure the authentication and recovery options available in your beta build.
- Support & correspondence. If you email us, we keep that correspondence to answer you.
Website security checks
When an online form is enabled, Cloudflare Turnstile processes browser and network signals to check for automated abuse. Our server sends your IP address and verification token to Cloudflare to validate the check. We use keyed hashes of IP addresses, email addresses, and submissions in Upstash Redis to limit repeated requests and suppress duplicates. These records expire within 24 hours; we do not store the raw message, email address, or IP address in those Redis records. Website form logs contain a request identifier and outcome, rather than your message or credentials. Hosting and verification providers may also maintain their own security logs.
Information created when you use the app
- Wallet metadata. To provide a watch-only view and coordinate signing, we process your vault's public keys (xpubs), output descriptors, Bitcoin addresses, and transaction history. Extended public keys and descriptors can reveal wallet activity beyond an individual transaction. We treat this information as sensitive and it can become identifying when linked to your account.
- Recovery records. When you initiate a recovery, we log the request, the cooling-period timeline, alerts sent, and the resulting signature, each with a correlation ID, for security and audit purposes.
- Device & technical data. Standard technical data needed to run a mobile app and secure service, such as device type, OS version, app version, push-notification tokens, IP address, and security/error logs.
What we do not collect or hold
- Your two signing keys. In the 2-of-3 design, your mobile and hardware keys remain under your control. Coinhost holds a separate recovery key, which cannot authorize a transaction alone. Do not send us private keys, seed phrases, PINs, or passwords.
- No KYC in v1. We do not collect government identification, and we do not run identity-verification (KYC) in the current version of the Services.
- No advertising trackers. We do not sell personal information and we do not use third-party advertising or cross-site tracking cookies.
3How we use information
- To provide, maintain, and secure the Services, including coordinating 2-of-3 signing and the recovery process you request.
- To respond to waitlist sign-ups, consultation requests, and support messages.
- To send service and security communications (for example, recovery alerts and important notices). We will only send marketing email with your consent, and you can unsubscribe at any time.
- To detect, prevent, and investigate fraud, abuse, and security incidents.
- To comply with legal obligations that apply to us.
Our legal bases for processing (where the GDPR applies) are performance of a contract, your consent, our legitimate interests in operating and securing the Services, and compliance with law.
4Service providers we share with
We do not sell your data. We share information only with vetted providers who process it on our behalf under contract, and only as needed to run the Services:
- Vercel — website and serverless hosting.
- Resend — consultation email delivery and waitlist contact storage.
- Cloudflare — Turnstile verification for website forms.
- Upstash — temporary, hashed records used to limit form abuse and duplicate submissions.
- Amazon Web Services — infrastructure for wallet services.
- Apple & Google — app distribution and push notifications, subject to their own privacy policies.
We may also disclose information if required by law, to enforce our Terms, or to protect the rights, safety, and property of our users or others.
5Data retention
We keep personal information only as long as needed for the purposes above or as required by law. Waitlist and consultation messages are kept until they are no longer needed and then deleted on request. Security and recovery audit logs are retained for a limited period appropriate to their security purpose. You can ask us to delete information we hold about you at any time.
6Security
The website uses encrypted connections and form-abuse controls, including verification, request limits, and duplicate suppression. These controls do not eliminate every risk. In the wallet's 2-of-3 design, Coinhost's recovery key alone cannot authorize a transaction; access to two keys can. See the Security model for the design, its limits, and beta status.
7Your rights
Depending on where you live, you may have the right to access, correct, delete, or port your personal information, to object to or restrict certain processing, and to withdraw consent. To exercise any of these, email privacy@coinhost.com. You also have the right to lodge a complaint with your local data-protection authority.
8International transfers
We are based in the United States and our providers may process data in the US and other countries. Where required, we rely on appropriate safeguards (such as standard contractual clauses) for international transfers.
9Children
The Services are not directed to anyone under 18, and we do not knowingly collect information from children. If you believe a child has provided us information, contact us and we will delete it.
10Changes to this policy
We may update this policy as the Services evolve. We will revise the "Last updated" date above and, for material changes, provide a more prominent notice. Continued use of the Services after a change means you accept the updated policy.
11Contact
Questions about privacy? Email privacy@coinhost.com.
254 Chapman Rd, Ste 208 #1535
Newark, Delaware 19702
United States